Allow NFS inbound from the cluster, give the EFS CSI driver an IAM role, and create a mount target in the node subnet
A DevOps engineer is building the infrastructure for an application. The application needs to run on an Amazon Elastic Kubernetes Service (Amazon EKS) cluster that includes Amazon EC2 instances. The EC2 instances need to use an Amazon Elastic File System (Amazon EFS) file system as a storage backend. The Amazon EFS Container Storage Interface (CSI) driver is installed on the EKS cluster. When the DevOps engineer starts the application, the EC2 instances do not mount the EFS file system. Which solutions will fix the problem? (Choose three.)
Community Votes
100% of anonymous learners picked answer BCE. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The failure is a mount failure, so every element on the data path must be correct: network reachability through the file system's security group allowing NFS (B), authorization for the CSI driver through an IAM role (C), and network topology through a mount target in the nodes' subnet (E). A mount target is per-subnet, so without one in the node subnet the file system simply is not reachable from those nodes. Option A would replace the compute entirely and is not a fix, and DataSync in option D is a data movement service that has no role in mounting a file system.
For EKS nodes to mount an EFS file system through the EFS CSI driver, three things must all be in place. The EFS file system's security group must allow inbound NFS traffic from the EKS cluster so the mount is not blocked, the CSI driver must have an IAM role permitting it to interact with the file system, and the file system must have a mount target in the subnet where the EKS nodes run, since a file system is only reachable through a mount target in each subnet where clients are located.
Switching the EKS nodes from EC2 to AWS Fargate (A) — that changes the compute substrate entirely rather than fixing the mount, and it would require the Fargate-specific considerations the scenario did not ask for. Setting up AWS DataSync to configure file transfer between the EFS file system and the EKS nodes (D) — DataSync moves data between storage services and cannot configure or perform a file system mount on a node. Omitting the mount target (the failure mode in the scenario) — an EFS file system requires a mount target in each subnet where instances mount it, so nodes in a subnet without one cannot mount the file system.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An EKS node mounting an EFS file system through the CSI driver depends on three independent prerequisites. Network reachability requires an inbound rule on the EFS file system's security group permitting NFS traffic from the EKS cluster, otherwise the mount connection on the NFS port is rejected (B). Authorization requires an IAM role that allows the Amazon EFS CSI driver to interact with the file system, without which the driver cannot perform the mount on the node's behalf (C). Network topology requires a mount target for the EFS file system in the subnet where the EKS nodes run, because EFS file systems are reached through mount targets and a mount target exists per subnet; without one in the node subnet the file system is simply not reachable from those nodes (E). All three are necessary, which is why the question asks for three solutions. B, C, and E are the correct combination.Why the Other Options Are Wrong
A switches the EKS nodes from Amazon EC2 to AWS Fargate. This replaces the compute substrate instead of repairing the mount, and it would bring its own considerations around Fargate storage that the scenario did not raise; the CSI driver is already installed on the cluster, so the driver itself is not the problem. D sets up AWS DataSync to configure file transfer between the EFS file system and the EKS nodes. DataSync is a managed service for transferring data between on-premises and AWS storage services or between AWS storage services; it has no capability to configure or perform a file system mount on an EKS node, so it cannot contribute to fixing the mount. B, C, and E are correct.Community Comment Notes
Community voted B,C,E unanimously. jamesf explained each element: the file system's security group must allow inbound NFS traffic from the cluster or the instances cannot communicate with the file system, and trungtd specified port 2049. trungtd also noted the CSI driver needs the necessary IAM permissions. KaranNishad enumerated all three required fixes. No alternative received support.Official Reference
Related Analysis
Practice All DOP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full DOP-C02 Practice Test →